<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Azure Compute Gallery — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/azure-compute-gallery/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 26 May 2026 13:32:50 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/azure-compute-gallery/feed.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-26147: Azure Compute Gallery Information Disclosure via Improper Input Validation</title><link>https://feed.craftedsignal.io/briefs/2026-05-azure-compute-gallery-info-disc/</link><pubDate>Tue, 26 May 2026 13:32:50 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-05-azure-compute-gallery-info-disc/</guid><description>CVE-2026-26147 is an improper input validation vulnerability in Azure Compute Gallery that allows an authorized attacker to disclose information over a network.</description><content:encoded><![CDATA[<p>CVE-2026-26147 describes an information disclosure vulnerability affecting the Azure Compute Gallery. The vulnerability stems from improper input validation within the service, potentially allowing an authorized attacker to gain unauthorized access to sensitive information over a network. While the specific details of the input validation flaw are not described in the source, the vulnerability is classified as HIGH severity with a CVSS score of 7.7. This vulnerability matters because it can lead to unauthorized disclosure of sensitive data stored within Azure Compute Gallery.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker authenticates to the Azure environment with valid credentials, gaining access to the Azure Compute Gallery.</li>
<li>The attacker crafts a malicious request targeting the Azure Compute Gallery API endpoint.</li>
<li>The malicious request exploits the improper input validation flaw by including specially crafted input.</li>
<li>The Azure Compute Gallery processes the malicious request without proper validation.</li>
<li>Due to the lack of input sanitization, the system leaks sensitive information.</li>
<li>The sensitive information is disclosed to the attacker over the network.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2026-26147 allows an authorized attacker to disclose sensitive information stored in the Azure Compute Gallery. The impact of this vulnerability is limited to information disclosure and does not allow for code execution, modification of data, or denial of service. The number of victims and the extent of the damage depend on the sensitivity of the data stored within the Azure Compute Gallery and the scope of the attacker&rsquo;s access.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the patch provided by Microsoft to remediate CVE-2026-26147 on Azure Compute Gallery as soon as possible (<a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26147)">https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26147)</a>.</li>
<li>Monitor Azure Compute Gallery logs for suspicious API requests containing unusual characters or patterns that may indicate exploitation attempts.</li>
<li>Implement and enforce strict input validation on all user-provided input to prevent similar vulnerabilities in the future.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>cve-2026-26147</category><category>information-disclosure</category><category>cloud</category></item></channel></rss>